POODLE SSLv3 vulnerability

Dag-Erling Smørgrav des at des.no
Wed Oct 15 09:15:41 UTC 2014


Eygene Ryabinkin <rea at freebsd.org> writes:
> I'd also introduce an OPTION for Apache, Nginx and other Web servers
> we ship in the ports collection that won't allow to use SSLv3 and turn
> it on by-default.  This will break some legacy clients, so it should
> be an OPTION.  stunnel, all Web servers for Ruby and other servers
> that do SSL should also be modified to include such modification.

That sounds like a good idea, but also a lot of work...

DES
-- 
Dag-Erling Smørgrav - des at des.no


More information about the freebsd-chromium mailing list